TIBCO Managed File Transfer Internet Server before 7.2.2, Managed File Transfer Command Center before 7.2.2, Slingshot before 1.9.1, and Vault before 1.0.1 allow remote attackers to obtain sensitive information via a crafted HTTP request.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.tibco.com/multimedia/mft_advisory_20140429_tcm8-21013.txt | vendor advisory |
http://www.tibco.com/mk/advisory.jsp | vendor advisory |